ChartGPT
Make a Chart Features Pricing Chart Types API
Company
About Blog Search Articles Careers Help Centre Contact
Account
Sign in Create an account

Home / Legal

Data processing

Who processes data on our behalf, and the terms that apply if you are a business customer.

Effective 1 August 2026 · Last updated 1 August 2026

If you use ChartGPT to process personal data belonging to other people — your customers, employees or survey respondents — you are the data controller and we act as your processor. This page sets out how that works.

Sub-processors

We use the following providers. Each is bound by contract to protect the data and to use it only to provide their service to us.

Provider What they do Where
OpenAI Turns prompts and data into chart specifications United States
Cloud hosting provider Application, database and file storage India (Mumbai)
Payment provider Subscription billing and invoicing India
Email delivery provider Transactional email United States
Analytics provider Aggregated usage measurement European Union

Notice of changes

We will give at least 30 days' notice before adding or replacing a sub-processor that handles customer content. If you object on reasonable data-protection grounds, tell us within that period and we will either find an alternative or let you cancel with a pro-rata refund.

Our commitments as a processor

  • We process personal data only on your documented instructions, which are the instructions you give through the service.
  • People with access are bound by confidentiality obligations.
  • We apply the technical and organisational measures described on the security page.
  • We help you respond to requests from individuals exercising their rights.
  • We notify you without undue delay if we become aware of a personal data breach affecting your data.
  • On termination we delete your data within 30 days, or return it if you ask before then — the same window as the privacy policy and the security page. Prompts, pasted data and charts are never stored, so there is nothing of that kind to return.

This agreement covers data you put into the service, where you are the controller and we act on your instructions. It does not cover comments posted in the discussion under our articles: there we are the controller, because we decide to publish them, and the privacy policy is the document that applies.

Your responsibilities

  • Have a lawful basis for the data you put into the service.
  • Tell the people concerned that their data may be processed by a service provider, where that notice is required.
  • Do not upload sensitive personal data — health, financial account, biometric or government identifiers. The service is not designed for it.

Signing a data processing agreement

If your organisation needs a countersigned DPA or standard contractual clauses, write to [email protected] with your template or ask for ours. We will not charge for this.


Questions about this document? Write to [email protected].